{"id":12766,"date":"2026-03-07T01:01:48","date_gmt":"2026-03-07T01:01:48","guid":{"rendered":"https:\/\/division.iium.edu.my\/itd\/?page_id=12766"},"modified":"2026-04-02T01:08:42","modified_gmt":"2026-04-02T01:08:42","slug":"isms-introduction","status":"publish","type":"page","link":"https:\/\/division.iium.edu.my\/itd\/isms-introduction\/","title":{"rendered":"ISMS &#8211; Introduction"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"12766\" class=\"elementor elementor-12766\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-bbeee7b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"bbeee7b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e79b433\" data-id=\"e79b433\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4dc7a77 elementor-widget elementor-widget-text-editor\" data-id=\"4dc7a77\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-sfc-cp=\"\" data-hveid=\"CAEIAhAA\" data-complete=\"true\" data-processed=\"true\"><h3><span style=\"color: #000000;\"><b>Introduction<\/b><\/span><\/h3><p><span style=\"color: #000000;\">What is <\/span><span style=\"color: #000000;\"><strong>ISO\/IEC 27001:2022?<\/strong><\/span><\/p><p data-start=\"139\" data-end=\"389\"><span style=\"color: #000000;\"><strong data-start=\"139\" data-end=\"161\">ISO\/IEC 27001:2022<\/strong> is a globally recognized international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an <strong data-start=\"316\" data-end=\"365\">Information Security Management System (ISMS)<\/strong> within an organization.<\/span><\/p><p data-start=\"391\" data-end=\"743\"><span style=\"color: #000000;\">This standard adopts a <strong data-start=\"414\" data-end=\"437\">risk-based approach<\/strong> to information security, enabling organizations to systematically identify, assess, and manage information security risks. It ensures that appropriate controls are implemented to safeguard sensitive information against threats such as unauthorized access, data breaches, cyberattacks, and system failures.<\/span><\/p><p data-start=\"745\" data-end=\"1115\"><span style=\"color: #000000;\">The ISMS framework integrates <strong data-start=\"775\" data-end=\"812\">people, processes, and technology<\/strong>, ensuring that information security is not treated as a standalone technical function but as a comprehensive organizational responsibility. It encompasses policies, procedures, guidelines, and associated resources designed to protect information assets in all forms\u2014digital, physical, and intellectual.<\/span><\/p><p data-start=\"1117\" data-end=\"1377\"><span style=\"color: #000000;\">The 2022 revision introduces updated controls aligned with current cybersecurity challenges, including cloud security, threat intelligence, data masking, and secure development practices, making it highly relevant in today\u2019s rapidly evolving digital landscape.<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4facbac elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4facbac\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1114ab1\" data-id=\"1114ab1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-22c266b elementor-widget elementor-widget-text-editor\" data-id=\"22c266b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-sfc-cp=\"\" data-hveid=\"CAEIAhAA\" data-complete=\"true\" data-processed=\"true\"><h3><span style=\"color: #000000;\">The Background<\/span><\/h3><p data-start=\"1408\" data-end=\"1556\"><span style=\"color: #000000;\">The implementation of ISO\/IEC 27001 within the university aligns with national directives and institutional strategic priorities, as outlined below:<\/span><\/p><ul data-start=\"1558\" data-end=\"3438\"><li data-section-id=\"1fah9f1\" data-start=\"1558\" data-end=\"2104\"><span style=\"color: #000000;\"><strong data-start=\"1560\" data-end=\"1580\">24 November 2010<\/strong><\/span><br data-start=\"1580\" data-end=\"1583\" \/><span style=\"color: #000000;\">The Malaysian Administrative Modernisation and Management Planning Unit (MAMPU), under the Prime Minister\u2019s Department, issued a directive titled <em data-start=\"1731\" data-end=\"1797\">\u201cPelaksanaan Pensijilan MS ISO\/IEC 27001:2007 Dalam Sektor Awam\u201d<\/em>.<\/span><br data-start=\"1798\" data-end=\"1801\" \/><span style=\"color: #000000;\">This initiative mandated all government agencies to adopt and implement ISO\/IEC 27001 certification to strengthen information security governance across the public sector. The directive marked the beginning of a structured, nationwide effort to enhance the protection of government information assets.<\/span><br \/><br \/><\/li><li data-section-id=\"1k768m1\" data-start=\"2106\" data-end=\"2510\"><span style=\"color: #000000;\"><strong data-start=\"2108\" data-end=\"2116\">2022<\/strong><\/span><br data-start=\"2116\" data-end=\"2119\" \/><span style=\"color: #000000;\">Under the <strong data-start=\"2131\" data-end=\"2229\">University Key Risk (UKR) No. 2: Comprehensive Information and Communication Technology Policy<\/strong>, ISMS certification was formally identified as a <strong data-start=\"2279\" data-end=\"2303\">required deliverable<\/strong>.<\/span><br data-start=\"2304\" data-end=\"2307\" \/><span style=\"color: #000000;\">This reflects the university\u2019s recognition of information security as a critical risk domain, particularly in safeguarding academic data, research outputs, administrative records, and digital services.<\/span><br \/><br \/><\/li><li data-section-id=\"1rqfuni\" data-start=\"2512\" data-end=\"2826\"><span style=\"color: #000000;\"><strong data-start=\"2514\" data-end=\"2533\">7 February 2024<\/strong><\/span><br data-start=\"2533\" data-end=\"2536\" \/><span style=\"color: #000000;\">The <strong data-start=\"2542\" data-end=\"2566\">IIUM ISMS initiative<\/strong> was officially approved during the <strong data-start=\"2602\" data-end=\"2662\">University Management Committee (UMC) Meeting No. 3\/2024<\/strong>.<\/span><br data-start=\"2663\" data-end=\"2666\" \/><span style=\"color: #000000;\">This approval signified top management commitment towards institutionalizing a structured information security framework aligned with international standards.<\/span><br \/><br \/><\/li><li data-section-id=\"1f0z7ea\" data-start=\"2828\" data-end=\"3083\"><span style=\"color: #000000;\"><strong data-start=\"2830\" data-end=\"2847\">11 March 2025<\/strong><\/span><br data-start=\"2847\" data-end=\"2850\" \/><span style=\"color: #000000;\">The <strong data-start=\"2856\" data-end=\"2897\">scope of the IIUM ISMS implementation<\/strong> was endorsed during the <strong data-start=\"2922\" data-end=\"2958\">ICT Committee Meeting No. 1\/2025<\/strong>.<\/span><br data-start=\"2959\" data-end=\"2962\" \/><span style=\"color: #000000;\">This milestone established the boundaries and applicability of ISMS across selected kulliyyahs, divisions, and systems.<\/span><br \/><br \/><\/li><li data-section-id=\"10fhvw3\" data-start=\"3085\" data-end=\"3438\"><span style=\"color: #000000;\"><strong data-start=\"3087\" data-end=\"3102\">23 May 2025<\/strong><\/span><br data-start=\"3102\" data-end=\"3105\" \/><span style=\"color: #000000;\">The <strong data-start=\"3111\" data-end=\"3141\">IIUM ISMS Kick-Off Meeting<\/strong> was successfully conducted, marking the formal commencement of the implementation phase.<\/span><br data-start=\"3230\" data-end=\"3233\" \/><span style=\"color: #000000;\">The session was chaired by <strong data-start=\"3262\" data-end=\"3316\">Prof. Emeritus Datuk Dr. Osman Bakar (IIUM Rector)<\/strong>, demonstrating strong leadership support and institutional commitment towards achieving ISO\/IEC 27001:2022 certification.<\/span><\/li><\/ul><p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-13269\" src=\"https:\/\/division.iium.edu.my\/itd\/wp-content\/uploads\/sites\/16\/2026\/03\/ISMS-Kick-Off-Meeting-2025-300x179.png\" alt=\"\" width=\"746\" height=\"445\" srcset=\"https:\/\/division.iium.edu.my\/itd\/wp-content\/uploads\/sites\/16\/2026\/03\/ISMS-Kick-Off-Meeting-2025-300x179.png 300w, https:\/\/division.iium.edu.my\/itd\/wp-content\/uploads\/sites\/16\/2026\/03\/ISMS-Kick-Off-Meeting-2025-1024x612.png 1024w, https:\/\/division.iium.edu.my\/itd\/wp-content\/uploads\/sites\/16\/2026\/03\/ISMS-Kick-Off-Meeting-2025-768x459.png 768w, https:\/\/division.iium.edu.my\/itd\/wp-content\/uploads\/sites\/16\/2026\/03\/ISMS-Kick-Off-Meeting-2025.png 1486w\" sizes=\"(max-width: 746px) 100vw, 746px\" \/><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction What is ISO\/IEC 27001:2022? ISO\/IEC 27001:2022 is a globally recognized international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)<\/p>\n","protected":false},"author":37,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":{"1":"page","2":"type-page","3":"status-publish","4":"hentry"},"_links":{"self":[{"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/pages\/12766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/comments?post=12766"}],"version-history":[{"count":30,"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/pages\/12766\/revisions"}],"predecessor-version":[{"id":13515,"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/pages\/12766\/revisions\/13515"}],"wp:attachment":[{"href":"https:\/\/division.iium.edu.my\/itd\/wp-json\/wp\/v2\/media?parent=12766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}